Getting Data In

How can I index Netflow?

Dan
Splunk Employee
Splunk Employee

I want to be able to search netflow data to find suspicious conversations (i.e. someone opening a connection and closing it right away). Is there a way to get a netflow feed into Splunk?

Tags (1)

NetFlow_Logic
Contributor

All previously existing versions of NetFlow Logic Splunk apps have been merged into one NetFlow for Splunk by NetFlow Logic App. See this link http://apps.splunk.com/app/489/

0 Karma

maverick
Splunk Employee
Splunk Employee

Netflow data is binary and, even though you could splunk it like that, it would not be useful in that form inside your Splunk GUI while searching. Therefore, the flow will need to be converted to humanly-readable text first via some NetFlow-2-Text converter, such as the ones mentioned at the "TrafficFlows" link provided in the previous answer.

Once converted to text, however, you could then easily setup Splunk to listen on any open tcp or udp port for incoming converted flow streams and just send the it directly to that port and SPlunk will index it in real time.

NetFlow_Logic
Contributor

"Splunk for NetFlow" App is replaced with "NetFlow for Splunk". See this link: http://splunk-base.splunk.com/apps/22328/netflow-for-splunk-powered-by-netflow-integrator

0 Karma

maverick
Splunk Employee
Splunk Employee

See this link for the Splunk for Netflow App: http://splunkbase.splunk.com/apps/All/4.x/app:Splunk+for+NetFlow

0 Karma

rayfoo
Path Finder
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...